Your funds stay on your exchange.
TIYlab places orders through limited API permissions. Security relies on several complementary controls and on the correct configuration of your account.
Funds remain under your control
Your assets stay on your own exchange. TIYlab never takes custody.
Withdrawals disabled
API keys must have no withdrawal access. Permissions are checked during onboarding.
Encrypted secrets
Stored API credentials are encrypted with AES-256-GCM and are never displayed in plain text.
IP restriction
IP whitelisting is required or strongly recommended depending on the exchange.
Continuous controls
Runtime guards, position reconciliation and alerts monitor operational inconsistencies.
Client isolation
Each API key belongs to one client and every bot state is stored separately.
Your part of security
Enable two-factor authentication on Telegram and your exchange, use a dedicated API key, review every permission and do not trade manually on the account operated by TIYlab.
No information system can fully eliminate market, exchange, availability or cybersecurity risks.